Disclaimer

SNORTID
Enter a Snort ID to lookup (e.g 1:269)

"Snort" is a registered trademark of Sourcefire, Inc.

Site owned and maintained by Liam Somerville

©2009 SnortID.com - Developed by Cook Computing

Search String: 1:2376

N.B.: Maximum of 50 results are displayed

SidSummaryImpact Detailed InformationAffected SystemsAttack ScenariosEase of AttackFalse PositiveFalse Negative Corrective ActionContributorsAdditional References
1:2376 This event is generated when an attempt is made to exploit a known vulnerability in Checkpoint VPN-1. Unauthorized administrative access to Checkpoint VPN-1 systems Checkpoint VPN-1, SecuRemote and SecureClient contain an error that affects the processing of large Certificate requests to the VPN service. By sending a large amount of data in the Certificate Request payload an attacker may cause a buffer overflow condition to occur, presenting an opportunity to execute code of their choosing with the privileges of the user running the service, usually root. CheckPoint Software FW-1 1.4.1 Service packs prior to SP6 CheckPoint Software FW-1 Next Generation FP1, FP0 CheckPoint Software VPN-1 1.4.1 SP5a CheckPoint Software VPN-1 Next Generation FP1, FP0 An attacker could supply a large Certificate Request payload containing code to be executed on the system. Proof of concept code exists. None known None known Upgrade to the latest non-affected version of the software Apply the appropriate vendor supplied patches Sourcefire Vulnerability Research Team Brian Caswell Nigel Houghton